Skip links

Google Suspends Open Source Bug Bounty Program Amid Surge in AI Submissions

Google has announced a temporary suspension of its open source bug bounty program, attributing the decision to a marked increase in submissions driven by artificial intelligence. This program, which rewarded researchers for identifying vulnerabilities in the company’s open source projects, will remain on hold until early next year.

Concerns regarding the impact of AI-generated reports on the integrity of bug bounty programs have been voiced by cybersecurity experts, as reported by TechCrunch last year. The surge in submissions largely consisted of invalid reports or those plagued by inaccuracies, often described as “hallucinations.”

In updates shared via X and on the program’s official website, Google confirmed that the pause took effect on October 1. The tech giant indicated it would provide further information during the first quarter of 2027. As reported by Tom’s Hardware, engineers at Google and open source maintainers have found the influx of submissions to be overwhelming, complicating their ability to assess and manage legitimate reports.

The company stated, “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.” In light of this development, participants are encouraged to explore other available bug bounty programs hosted by Google.

Editor’s Take

The suspension of Google’s open source bug bounty program is significant as it reflects growing concerns about the reliability of AI-generated content. For users and developers alike, this could mean a reassessment of the authenticity of reported vulnerabilities. The tech community must now navigate this complex landscape where the quality of submissions may be compromised, potentially delaying vital security improvements in open source software.

Source: techcrunch.com

Leave a comment